Joomboost Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Joomboost products.
Products
- JoomCRM1 vulnerability
- Joomla JoomRecipe1 vulnerability
- JoomProject1 vulnerability
- JoomRecipe1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25762HIGH | Joomla! Component JoomProject 1.1.3.2 Information DisclosureJoomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format. CWE-359Jun 19, 2026 | CVSS8.7v4.0 | EPSS0.54% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25761HIGH | Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_idJoomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to index.php with option=com_joomcrm&view=contacts and inject SQL code in the deal_id parameter to extract sensitive database information including table names and schemas. CWE-89Jun 19, 2026 | CVSS7.1v4.0 | EPSS0.367% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-20278HIGH | Joomla JoomRecipe 1.0.3 SQL Injection via category parameterJoomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category path segment to extract sensitive database information. CWE-89Jun 19, 2026 | CVSS8.8v4.0 | EPSS0.394% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-20277HIGH | Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_authorJoomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques. CWE-89Jun 19, 2026 | CVSS8.8v4.0 | EPSS0.412% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |